Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
NocoDB: Missing Ownership Validation in MCP Token Operations
Vulnerability Description
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not validate token ownership, allowing a Creator within the same base to read, regenerate, or delete another user's MCP tokens if the token ID was known. This issue has been patched in version 0.301.3.
CVSS Information
N/A
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
NocoDB 安全漏洞
Vulnerability Description
NocoDB是nocodb开源的一个 Airtable 替代品。将任何 MySql、PostgreSql、Sql Server、Sqlite 和 MariaDb 转换为智能电子表格。 NocoDB 0.301.3之前版本存在安全漏洞,该漏洞源于MCP令牌服务未验证令牌所有权,可能导致同一基础内的用户读取、重新生成或删除他人的MCP令牌。
CVSS Information
N/A
Vulnerability Type
N/A